CVE-2018-6464: Mycolorway Simditor
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
Affected products
- Mycolorway Simditor: version 2.3.11 only
Published 2018-01-31. Last modified 2026-06-17.